Access Control Vulnerability in FreeScout Help Desk Software
CVE-2025-48473
5.3MEDIUM
What is CVE-2025-48473?
FreeScout, a self-hosted help desk software, had a significant access control vulnerability prior to version 1.8.179. This flaw allowed users to create conversations from messages in other conversations without appropriate visibility checks. Consequently, unauthorized users could access arbitrary messages from different mailboxes or conversations they were not meant to view. The oversight stemmed from a lack of validation against the 'show_only_assigned_conversations' setting, which is intended to restrict access. This issue was addressed in version 1.8.179 to enhance security measures.
Affected Version(s)
freescout < 1.8.179